Agent skill

Bash Herestring Newline Secrets

by divinevideo in divinevideo/divine-mobile

Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings.

MPL-2.0Auto-check passedBackend & APIs

Install Bash Herestring Newline Secrets

skills CLI
$ npx skills add divinevideo/divine-mobile --skill bash-herestring-newline-secrets -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install divinevideo/divine-mobile bash-herestring-newline-secrets --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/bash-herestring-newline-secrets .claude/skills/bash-herestring-newline-secrets && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
bash-herestring-newline-secrets
GitHub stars
265
Token cost
~791 tokens
SKILL.md length
192 words
Files
1
Skills in repo
103
Repo updated
First seen
Licence
MPL-2.0

At a glance

Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings.

  • Password authentication fails with correct password
  • SKILL.md covers Problem, Context / Trigger Conditions, Solution and Verification, plus 3 more sections
  • Calls gcloud
  • Secret created with <<< value syntax

What it does

Bash Herestring Newline Secrets is an agent skill from divinevideo/divine-mobile. Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings. Use when: (1) Password authentication fails with correct password, (2) Secret created with <<< "value" syntax, (3) Error like "password authentication failed" or "invalid token" despite correct value. Bash here-strings (<<<) add a trailing newline that corrupts secrets.

Its SKILL.md is about 790 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication. It works with Bash and Google Cloud. The licence is MPL-2.0.

When your agent uses it

  • Password authentication fails with correct password
  • Secret created with <<< value syntax
  • Error like password authentication failed
  • Invalid token despite correct value

Example prompts

  • “syntax, (3) Error like”
  • “invalid token”
  • “/bash-herestring-newline-secrets”

What it can do on your machine

Read from SKILL.md and the folder at commit 8d5fbf2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • gnu.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Bash Herestring Newline Secrets loads about 791 tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 192 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~791

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from divinevideo/divine-mobile at commit 8d5fbf2, republished under its MPL-2.0 licence (© divinevideo). 192 words, ~791 tokens.

Download SKILL.mdSave it as .claude/skills/bash-herestring-newline-secrets/SKILL.md (or your agent's skills folder).
name
bash-herestring-newline-secrets
description
Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings. Use when: (1) Password authentication fails with correct password, (2) Secret created with `<<< "value"` syntax, (3) Error like "password authentication failed" or "invalid token" despite correct value. Bash here-strings (`<<<`) add a trailing newline that corrupts secrets.
author
Claude Code
version
1.0.0
date
2026-01-31

Bash Here-String Newline in Secrets

Problem

When creating secrets using bash here-strings (<<<), a trailing newline is silently appended to the value. This causes authentication failures with misleading error messages that suggest the password/token is wrong when it's actually correct—just with an extra newline character.

Context / Trigger Conditions

  • Secret created with: gcloud secrets create NAME --data-file=- <<< "value"
  • Or similar: echo "value" | gcloud secrets create... (echo adds newline by default)
  • Error messages like:
    • "password authentication failed for user X"
    • "invalid token"
    • "authentication failed"
  • The secret value appears correct when viewed
  • Works locally but fails when secret is used

Solution

Wrong (adds newline):

bash
gcloud secrets create my-secret --data-file=- <<< "mypassword"
echo "mypassword" | gcloud secrets create my-secret --data-file=-

Correct (no newline):

bash
echo -n "mypassword" | gcloud secrets create my-secret --data-file=-
printf '%s' "mypassword" | gcloud secrets create my-secret --data-file=-

To fix an existing secret:

bash
echo -n "correct-value" | gcloud secrets versions add my-secret --data-file=-

Verification

Check the secret length to detect trailing newline:

bash
# Get secret and count bytes
gcloud secrets versions access latest --secret=my-secret | wc -c
# Compare to expected length (password length, not password length + 1)

Or use xxd to see the actual bytes:

bash
gcloud secrets versions access latest --secret=my-secret | xxd | tail -1
# Look for '0a' (newline) at the end

Example

Symptom:

Database connection test failed: password authentication failed for user "crawler"

Investigation:

bash
$ gcloud secrets versions access latest --secret=my-db-password
mypassword
$ gcloud secrets versions access latest --secret=my-db-password | wc -c
11  # But password is only 10 characters!

Fix:

bash
$ echo -n "mypassword" | gcloud secrets versions add my-db-password --data-file=-
Created version [2] of the secret [my-db-password].

Notes

  • This affects any system that uses secrets: databases, APIs, tokens, etc.
  • The <<< here-string is a bash feature that ALWAYS adds a newline
  • echo also adds a newline by default; use echo -n or printf '%s'
  • Some systems trim whitespace from secrets, but many (like PostgreSQL) don't
  • When debugging auth failures, always check for trailing whitespace first

References

© divinevideo, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/bash-herestring-newline-secrets of divinevideo/divine-mobile.

Open the folder on GitHubat commit 8d5fbf2

Compare with similar skills

Bash Herestring Newline Secrets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Bash Herestring Newline Secrets compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Bash Herestring Newline Secrets this skilldivinevideo/divine-mobile265—~791Automated safety check: PassMPL-2.0
Atmos Authcloudposse/atmos1.4k—~4.2kAutomated safety check: PassApache-2.0
Managing Cloud Identity With Oktamukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Iam Auditbriiirussell/cybersecurity-skills412—~3.1kAutomated safety check: NotesMIT
Dpop Adoptiongoogle/skills21k—~2.8kAutomated safety check: PassApache-2.0
Data Manager API Setupgoogle/skills21k—~704Automated safety check: PassApache-2.0

Similar skills

  • Atmos Auth

    cloudposse/atmos

    Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access

    1.4k GitHub stars~4.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Managing Cloud Identity With Okta

    mukul975/Anthropic-Cybersecurity-Skills

    Implement Okta as a centralized cloud identity provider: configure SSO with AWS, Azure, and GCP, deploy phishing-resistant MFA with Okta FastPass, automate user provisioning/deprovisioning, and…

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    412 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Dpop Adoption

    google/skills

    Official

    Implement and debug OAuth 2.0 DPoP (RFC 9449) refresh token sender-constraining for WebCrypto, Node.js ES6, and browser runtimes integrating with Google's OAuth platform.

    21k GitHub stars~2.8k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Official

    Guides developers through client library installation and authentication setup steps for the Data Manager API.

    21k GitHub stars~704 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Clerk Auth

    LeoYeAI/openclaw-master-skills

    Clerk auth with API Keys beta (Dec 2025), Next.js 16 proxy.ts (March 2025 CVE context), API version 2025-11-10 breaking changes, clerkMiddleware() options, webhooks, production considerations (GCP…

    2.2k GitHub stars~6.1k tokensUpdated 2 mo ago
    Backend & APIsAuto-check: notes

More from divinevideo/divine-mobile

All 103 skills in this repo
  • Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y".

    265 GitHub stars~931 tokensUpdated today
    Auto-check passed
  • Art Direct

    divinevideo/divine-mobile

    Art direction for any content — reads text, PDF, Word, HTML, PPT, then proposes 2-3 creative directions with photography style, mood, and visual language.

    265 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Async Await Null Race Condition

    divinevideo/divine-mobile

    Fix "Null check operator used on a null value" errors when an object is set to null during an async await.

    265 GitHub stars~881 tokensUpdated today
    Auto-check passed
  • AWS V4 Signing Custom Headers Gcs

    divinevideo/divine-mobile

    Add custom metadata headers (x-amz-meta-) to AWS v4 signed requests for GCS S3-compatible API.

    265 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Fix silent video/media processing failures caused by URL extraction code that filters on file extensions (.mp4, .webm, .webp).

    265 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Certmanager Dns01 Gke Private Cluster

    divinevideo/divine-mobile

    Fix cert-manager DNS01 ACME challenges stuck in "pending" state with "DNS record not yet propagated" inside GKE private clusters, even when TXT records exist in Cloudflare DNS.

    265 GitHub stars~1.8k tokensUpdated today
    Auto-check passed

Categories

Questions about Bash Herestring Newline Secrets

What does Bash Herestring Newline Secrets do?

Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings. Bash Herestring Newline Secrets is an agent skill from divinevideo/divine-mobile. Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings.

When should I use Bash Herestring Newline Secrets?

Bash Herestring Newline Secrets fits situations like: password authentication fails with correct password; secret created with <<< value syntax; error like password authentication failed; invalid token despite correct value.

How do I install Bash Herestring Newline Secrets in Claude Code?

Run `npx skills add divinevideo/divine-mobile --skill bash-herestring-newline-secrets -a claude-code`. Or copy the skill folder (.agents/skills/bash-herestring-newline-secrets in divinevideo/divine-mobile) into .claude/skills/bash-herestring-newline-secrets in your project. Claude Code loads it when a task matches its description.

How do I install Bash Herestring Newline Secrets in Codex?

Run `npx skills add divinevideo/divine-mobile --skill bash-herestring-newline-secrets -a codex`. Or copy the skill folder (.agents/skills/bash-herestring-newline-secrets in divinevideo/divine-mobile) into .agents/skills/bash-herestring-newline-secrets in your project. Codex loads it when a task matches its description.

Can I use Bash Herestring Newline Secrets in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add divinevideo/divine-mobile --skill bash-herestring-newline-secrets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/bash-herestring-newline-secrets, .gemini/skills/bash-herestring-newline-secrets, .github/skills/bash-herestring-newline-secrets and .opencode/skills/bash-herestring-newline-secrets in your project.

What does Bash Herestring Newline Secrets need to run?

Going by SKILL.md and its folder, Bash Herestring Newline Secrets needs the command-line tools its instructions call (gcloud).

Does Bash Herestring Newline Secrets access the network?

SKILL.md names 1 domain. As links in the text: gnu.org. This is read from the text; nothing was executed.

Is Bash Herestring Newline Secrets safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Bash Herestring Newline Secrets use?

Bash Herestring Newline Secrets is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Bash Herestring Newline Secrets use?

About 791 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Bash Herestring Newline Secrets?

Skills that share tags, products or a category with Bash Herestring Newline Secrets: Atmos Auth (cloudposse/atmos, 1.4k stars), Managing Cloud Identity With Okta (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Iam Audit (briiirussell/cybersecurity-skills, 412 stars) and Dpop Adoption (google/skills, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Bash Herestring Newline Secrets?

divinevideo (a GitHub organization) maintains it in divinevideo/divine-mobile, which has 265 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 7, 2026.

Source: divinevideo/divine-mobile on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.